Passal is an educational study product for students. You upload your own lecture materials; Passal turns them into study cards and quizzes that quote your source, or it refuses when it cannot cite. Passal does not give medical advice. This privacy policy describes how Passal handles personal information, including when you sign in with Google.
Passal is operated by Dave Bettner (the “operator”). Contact for privacy and account requests: [email protected]. Related terms of use: Terms.
Google sign-in
You can create or open a Passal account with Google Sign-In on the study app at study.passal.app/login. When you choose Google, Google shows its consent screen and Passal receives only the account information needed to authenticate you.
Google user data Passal receives: your Google account email address, your Google account name, and your Google profile picture URL when Google provides one. Passal does not receive your Google password.
OAuth scopes Passal requests for Google sign-in:
openid— verify your Google identityemail— read your Google account email addressprofile— read your basic Google profile (name and profile picture, when available)
Those are the sign-in scopes. Google Drive and Google Calendar are optional and described in the next section; Passal asks for them only when you choose to connect them, and Google shows its consent screen before either is granted.
How Google sign-in data is used: to create and secure your Passal account, keep you signed in, show your name or avatar in the study app, and sync your study data to that account. Passal does not use Google user data for advertising, does not sell it, and does not use it to train models.
Sharing of Google user data: Passal does not sell Google user data. It is not shared with other users. Limited processors that host or deliver the service may process it only to run Passal (see Sharing and subprocessors below). Passal’s use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Google Drive and Google Calendar (optional)
Google Drive — scope https://www.googleapis.com/auth/drive.file. Requested only when you choose “Add lecture from Drive”. You pick a PDF or PowerPoint file in Google’s own file picker; with this scope Google lets Passal open only the files you pick, never the rest of your Drive, and Passal cannot browse folders. For each picked file Passal reads its name, type and size and downloads its contents once, then stores a copy in your Passal course as a lecture, exactly like a file you upload yourself. Passal never creates, changes or deletes anything in your Drive.
Google Calendar — scope https://www.googleapis.com/auth/calendar.events.readonly. Requested only when you choose to connect your calendar. Each time your calendar syncs, Passal reads events from your primary calendar for the next 14 days and keeps only each event’s title, start and end time and ID. It never requests event descriptions, locations or guests. Passal uses these events to show your upcoming exams and deadlines next to your study plan, to suggest which events look like exams from their titles, and, when you tag an event as an exam for a course, to move that course’s reviews earlier so they fall before it. Passal never creates, changes or deletes calendar events.
Storage and security: Drive and Calendar access tokens are stored on Passal’s server encrypted (AES-256-GCM) and used only for the actions above. The file-picker window in your browser receives only a short-lived access token.
Deletion: “Forget Drive access” deletes Passal’s Drive tokens. Disconnecting your calendar deletes its tokens and every stored event. Deleting your account deletes all of these, plus lectures imported from Drive. You can also remove Passal’s access at any time from your Google Account at myaccount.google.com/connections.
Sharing: Google Drive and Calendar data is not sold, not used for advertising, not used to train AI models, and not shared with other users. Calendar data is never sent to any AI provider. A lecture imported from Drive is treated like any other lecture you upload: it is sent to an AI provider only if you choose to use your own AI assistant or turn on AI drafting, as described under “Using your own AI”. Passal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Other account and study data Passal stores
- Account: email, display name, sign-in provider identifier (Google, Microsoft, Apple, or email code). Passal does not store a password for Google sign-in.
- Your materials: uploaded files, extracted text, and the cards, quizzes, and study guides made from that text.
- Study history: reviews, quiz answers, exam dates, and settings used to schedule what to study next.
- Optional connected services: if you connect Google Drive, Microsoft OneDrive, or a calendar, encrypted access tokens for the files or events you choose.
How Passal uses this data
Passal uses your data only to operate the study product for you: authenticate your account, store your lectures and cards, run recall and quizzes, and provide account settings. By default, cards and quizzes are generated on Passal’s servers from your source text. Passal does not sell personal data, does not use it for advertising, and does not use your materials to train models by default. Passal does not use advertising or analytics trackers on the study product.
Retention and deletion
Passal keeps your account and study data while your account is active. From Settings in the study app you can export study metadata or delete your account. You can also delete an individual source or course. Deleting your account removes your uploaded files, extracted text, cards, study history, AI drafting settings, and connected-service tokens. Passal may retain limited records (such as email, provider, provider account id, and deletion time) solely so an old session cannot restore a deleted account; signing in again later starts a new, empty account.
To request deletion by email instead of Settings, write to [email protected].
Sharing and subprocessors
Passal does not sell your personal information. Passal shares data only with processors needed to run the service, for example:
- Google, Microsoft, or Apple, when you sign in with them or connect their drive or calendar services
- Hosting and content delivery for passal.app and study.passal.app (including Cloudflare)
- Resend, if you use email sign-in codes (email address and code only)
- An AI provider you deliberately connect or enable, under that provider’s terms, only for the drafting path you choose
Processors may only use the data to provide their service to Passal, not for their own advertising.
Children
Passal is aimed at students in higher education and similar study settings. It is not directed to children under 13, and Passal does not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact [email protected] and we will delete it.
Using your own AI (optional)
You may choose to draft more cards with an AI assistant you already use. With a connector, after you approve Passal’s consent screen, that assistant can read course names, extracted lecture text, and existing cards and can add drafts. It cannot change or delete your data or see reviews, study history, or account details. You can disconnect it in Settings. With copy and paste, you choose what leaves your device. Lecture text sent to an assistant is processed under that provider’s terms, not Passal’s. Passal keeps a suggested card only when its quote appears word for word in your lecture.
Medical and sensitive content
Passal is for course materials. Do not upload patient records, clinical notes, or anything that identifies a patient. Passal is not designed for protected health information and does not provide medical advice.
Contact
Privacy questions, data requests, or account help: [email protected]. Terms of use: https://passal.app/terms/.